Am 18.06.26 um 16:42 schrieb William Herrin:
I'm almost never looking for a stateful packet inspector that isn't
doing NAT.  Stateful gives it most of the same drawbacks of NAT
without the benefit of making my internal network inaddressible from
outside. But YMMV: a lot of folks don't have the comfort level with
stateless packet filters that I do, and SPIs do offer some additional
protection to hosts intended to be reached from the Internet.

If you really want, you can combine SPI firewalling with NAT66 (1:1 matching if you want).

For me, NAT and the aspect that the machines are not addressable from the outside is a large disadvantage.

I do whatever I can with IPv6.

--
Gruß
Marco

Junk-Mail bitte an [email protected]
_______________________________________________
NANOG mailing list https://lists.nanog.org/archives/list/[email protected]/message/MDZP77OG5ZDCV6TWIAIXNCUZYDDHYYIF/

Reply via email to